First off, I totally agree with daedal, reputable companies will not give you any issues, and you should always limit access only to what is required.

Did you give them full root access to your server? If yes, I would ask your hosting company to scan for rootkits and back doors if you are concerned. Plus check over the php code to see if there are any unusual things, like iframes or base64 encoded stuff.